|
347251
|
7.5 |
HIGH
|
apple
|
quicktime mac_os_x mac_os_x_server
|
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.
|
NVD-CWE-Other
|
CVE-2004-0921
|
2008-09-6 05:39 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347252
|
5.0 |
MEDIUM
|
apple
|
quicktime mac_os_x mac_os_x_server
|
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is…
|
NVD-CWE-Other
|
CVE-2004-0922
|
2008-09-6 05:39 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347253
|
5.0 |
MEDIUM
|
easy_software_products apple
|
cups mac_os_x mac_os_x_server
|
NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.
|
NVD-CWE-Other
|
CVE-2004-0924
|
2008-09-6 05:39 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347254
|
10.0 |
HIGH
|
easy_software_products apple
|
cups mac_os_x mac_os_x_server
|
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
|
NVD-CWE-Other
|
CVE-2004-0926
|
2008-09-6 05:39 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347255
|
5.0 |
MEDIUM
|
easy_software_products apple
|
cups mac_os_x mac_os_x_server
|
ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.
|
NVD-CWE-Other
|
CVE-2004-0927
|
2008-09-6 05:39 |
2005-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347256
|
5.0 |
MEDIUM
|
-
|
-
|
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessio…
|
NVD-CWE-Other
|
CVE-2004-0944
|
2008-09-6 05:39 |
2004-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347257
|
5.0 |
MEDIUM
|
mitel
|
mitel_3300_integrated_communication_platform
|
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large n…
|
NVD-CWE-Other
|
CVE-2004-0945
|
2008-09-6 05:39 |
2005-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347258
|
5.0 |
MEDIUM
|
stonesoft
|
firewall_engine
|
The H.323 protocol agent in StoneSoft firewall engine 2.2.8 and earlier allows remote attackers to cause a denial of service (crash) via crafted H.323 packets.
|
NVD-CWE-Other
|
CVE-2004-0498
|
2008-09-6 05:38 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347259
|
7.5 |
HIGH
|
university_of_minnesota
|
gopherd
|
Integer overflow in gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted content of a certain size that triggers the over…
|
NVD-CWE-Other
|
CVE-2004-0560
|
2008-09-6 05:38 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347260
|
7.5 |
HIGH
|
university_of_minnesota
|
gopherd
|
Format string vulnerability in the log routine for gopher daemon (gopherd) 3.0.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2004-0561
|
2008-09-6 05:38 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347261
|
7.5 |
HIGH
|
phpgroupware
|
phpgroupware
|
Multiple SQL injection vulnerabilities in the (1) calendar and (2) infolog modules for phpgroupware 0.9.14 allow remote attackers to perform unauthorized database operations.
|
NVD-CWE-Other
|
CVE-2004-0017
|
2008-09-6 05:37 |
2004-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347262
|
7.5 |
HIGH
|
mod_auth_shadow
|
mod_auth_shadow
|
The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2004-0041
|
2008-09-6 05:37 |
2004-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347263
|
6.8 |
MEDIUM
|
realnetworks
|
helix_universal_mobile_server helix_universal_server
|
Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port.
|
NVD-CWE-Other
|
CVE-2004-0049
|
2008-09-6 05:37 |
2004-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347264
|
7.5 |
HIGH
|
nortel
|
business_communications_manager 802.11_wireless_ip_gateway succession_communication_server_1000
|
Multiple vulnerabilities in the H.323 protocol implementation for Nortel Networks Business Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, and 802.11 Wireless IP Gatewa…
|
NVD-CWE-Other
|
CVE-2004-0056
|
2008-09-6 05:37 |
2004-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347265
|
10.0 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Unknown vulnerability in Windows File Sharing for Mac OS X 10.1.5 through 10.3.2 does not "shutdown properly," which has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2004-0090
|
2008-09-6 05:37 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347266
|
5.0 |
MEDIUM
|
apache
|
mod_python
|
Unknown vulnerability in mod_python 2.7.9 allows remote attackers to cause a denial of service (httpd crash) via a certain query string, a variant of CAN-2003-0973.
|
NVD-CWE-Other
|
CVE-2004-0096
|
2008-09-6 05:37 |
2004-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347267
|
5.0 |
MEDIUM
|
gnu
|
mailman
|
Mailman before 2.0.13 allows remote attackers to cause a denial of service (crash) via an email message with an empty subject field.
|
NVD-CWE-Other
|
CVE-2004-0182
|
2008-09-6 05:37 |
2004-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347268
|
7.5 |
HIGH
|
phorum
|
phorum
|
Unspecified vulnerability in Phorum 3.4 through 3.4.2 allows remote attackers to use Phorum as a connection proxy to other sites via (1) register.php or (2) login.php.
|
NVD-CWE-Other
|
CVE-2003-1466
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347269
|
7.2 |
HIGH
|
freebsd
|
slashem-tty
|
slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privileges to modify slashem-tty and execute arbitrary c…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2003-1474
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347270
|
2.1 |
LOW
|
cerberus
|
ftp_server
|
Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.
|
NVD-CWE-Other
|
CVE-2003-1476
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347271
|
4.6 |
MEDIUM
|
microsoft
|
mn-500_wireless_base_station
|
The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access.
|
CWE-255
Credentials Management
|
CVE-2003-1482
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347272
|
5.0 |
MEDIUM
|
clearswift
|
mailsweeper
|
Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space."
|
CWE-20
Improper Input Validation
|
CVE-2003-1485
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347273
|
4.6 |
MEDIUM
|
snert.com
|
mod_throttle
|
mod_throttle 3.0 allows local users with Apache privileges to access shared memory that points to a file that is writable by the apache user, which could allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2003-1502
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347274
|
4.3 |
MEDIUM
|
mirc
|
mirc
|
Buffer overflow in mIRC 6.12, when the DCC get dialog window has been minimized and the user opens the minimized window, allows remote attackers to cause a denial of service (crash) via a long filena…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2003-1508
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347275
|
4.3 |
MEDIUM
|
bajie
|
java_http_server
|
Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the g…
|
CWE-79
Cross-site Scripting
|
CVE-2003-1511
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347276
|
5.0 |
MEDIUM
|
khaled_mardam-bey
|
mirc
|
Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2003-1512
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347277
|
6.8 |
MEDIUM
|
sun
|
java_plug-in
|
The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote …
|
NVD-CWE-Other
|
CVE-2003-1516
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347278
|
6.8 |
MEDIUM
|
fuzzymonkey
|
myclassifieds
|
SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.
|
CWE-89
SQL Injection
|
CVE-2003-1520
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347279
|
6.4 |
MEDIUM
|
sun
|
java_plug-in
|
Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates t…
|
NVD-CWE-Other
|
CVE-2003-1521
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347280
|
5.0 |
MEDIUM
|
francisco_burzi
|
php-nuke
|
PHP-Nuke 7.0 allows remote attackers to obtain the installation path via certain characters such as (1) ", (2) ', or (3) > in the search field, which reveals the path in an error message.
|
CWE-200
Information Exposure
|
CVE-2003-1526
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347281
|
4.3 |
MEDIUM
|
ibm iss
|
internet_security_systems_blackice_defender blackice_server_protection
|
BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packet…
|
NVD-CWE-Other
|
CVE-2003-1527
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347282
|
5.0 |
MEDIUM
|
postnuke_software_foundation
|
postnuke
|
Directory traversal vulnerability in PostNuke 0.723 and earlier allows remote attackers to include arbitrary files named theme.php via the theme parameter to index.php.
|
CWE-22
Path Traversal
|
CVE-2003-1537
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347283
|
6.4 |
MEDIUM
|
suse
|
suse_linux_openexchange_server office_server suse_linux
|
susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands vi…
|
CWE-20
Improper Input Validation
|
CVE-2003-1538
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347284
|
4.3 |
MEDIUM
|
onedotoh
|
simple_file_manager
|
Cross-site scripting (XSS) vulnerability in ONEdotOH Simple File Manager (SFM) before 0.21 allows remote attackers to inject arbitrary web script or HTML via (1) file names and (2) directory names.
|
CWE-79
Cross-site Scripting
|
CVE-2003-1539
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347285
|
5.0 |
MEDIUM
|
ondrej_jombik
|
phpwebfilemanager
|
Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter.
|
CWE-22
Path Traversal
|
CVE-2003-1542
|
2008-09-6 05:37 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347286
|
5.0 |
MEDIUM
|
ssh
|
secure_shell
|
SSH Secure Shell before 3.2.9 allows remote attackers to cause a denial of service via malformed BER/DER packets.
|
NVD-CWE-Other
|
CVE-2003-1119
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347287
|
5.0 |
MEDIUM
|
sun
|
one_directory_server
|
Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt).
|
NVD-CWE-Other
|
CVE-2003-1125
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347288
|
5.0 |
MEDIUM
|
sun
|
one_web_server
|
Unknown vulnerability in SunOne/iPlanet Web Server SP3 through SP5 on Windows platforms allows remote attackers to cause a denial of service.
|
NVD-CWE-Other
|
CVE-2003-1126
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347289
|
5.0 |
MEDIUM
|
cisco
|
content_services_switch_11000 content_services_switch_11500
|
The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0…
|
NVD-CWE-Other
|
CVE-2003-1132
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347290
|
2.1 |
LOW
|
sun
|
java
|
Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of genera…
|
NVD-CWE-Other
|
CVE-2003-1134
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347291
|
2.6 |
LOW
|
yahoo
|
messenger
|
Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo…
|
NVD-CWE-Other
|
CVE-2003-1135
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347292
|
5.0 |
MEDIUM
|
redhat
|
interchange
|
The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto indexing is turned off and there is a default web page …
|
NVD-CWE-Other
|
CVE-2003-1138
|
2008-09-6 05:36 |
2003-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347293
|
6.8 |
MEDIUM
|
john_beatty
|
easy_php_photo_album
|
Cross-site scripting (XSS) vulnerability in John Beatty Easy PHP Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
|
NVD-CWE-Other
|
CVE-2003-1146
|
2008-09-6 05:36 |
2003-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347294
|
7.2 |
HIGH
|
linux
|
linux_kernel
|
exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the s…
|
NVD-CWE-Other
|
CVE-2003-1161
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347295
|
5.0 |
MEDIUM
|
-
|
-
|
HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message.
|
NVD-CWE-Other
|
CVE-2003-1168
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347296
|
7.2 |
HIGH
|
gernot_stocker
|
kpopup
|
Format string vulnerability in main.cpp in kpopup 0.9.1 and 0.9.5pre2 allows local users to cause a denial of service (segmentation fault) and possibly execute arbitrary code via format string specif…
|
NVD-CWE-Other
|
CVE-2003-1170
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347297
|
5.0 |
MEDIUM
|
-
|
-
|
BRW WebWeaver 1.03 allows remote attackers to obtain sensitive server environment information via a URL request for testcgi.exe, which lists the values of environment variables and the current workin…
|
NVD-CWE-Other
|
CVE-2003-1235
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347298
|
10.0 |
HIGH
|
tanne
|
tanne
|
Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.
|
NVD-CWE-Other
|
CVE-2003-1236
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347299
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting vulnerability (XSS) in WWWBoard 2.0A2.1 and earlier allows remote attackers to inject arbitrary HTML or web script via a message post.
|
NVD-CWE-Other
|
CVE-2003-1237
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347300
|
5.8 |
MEDIUM
|
nuked-klan
|
nuked-klan
|
Cross-site scripting vulnerability (XSS) in Nuked-Klan 1.3 beta and earlier allows remote attackers to steal authentication information via cookies by injecting arbitrary HTML or script into op of th…
|
NVD-CWE-Other
|
CVE-2003-1238
|
2008-09-6 05:36 |
2003-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|